CVE-2026-33377: Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove or restrict the Editor role's write/overwrite permissions on dashboards so Editors cannot modify dashboards they do not own. Grant write access only to trusted users or administrators as required.
Dashboard permissions Editor role write access to dashboards = restricted/disabled - Configuration
Disable automatic overwriting of existing dashboards' ACLs during dashboard import, or require explicit administrator confirmation before an import can overwrite ACLs.
Dashboard import Overwrite ACLs on import = disabled or require confirmation - Compensating control
Restrict dashboard import and overwrite operations to administrators or a small set of trusted users until a permanent fix is implemented.
- Operational
Audit existing dashboards for unexpected or unauthorized admin assignments, revert any ACLs that were overwritten, and monitor dashboard ACL changes for signs of exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33377?
The severity of CVE-2026-33377 is rated as high with a score of 7.1.
How does CVE-2026-33377 allow privilege escalation?
CVE-2026-33377 allows an Editor to overwrite a dashboard not owned by them, thereby acquiring admin privileges on that specific dashboard.
What access is required to exploit CVE-2026-33377?
To exploit CVE-2026-33377, the user must have write access to the dashboard.
Which software is affected by CVE-2026-33377?
CVE-2026-33377 affects the Grafana software.
When was CVE-2026-33377 published?
CVE-2026-33377 was published on May 13, 2026.